### [CVE-2019-15092](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15092) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class. ### POC #### Reference - http://packetstormsecurity.com/files/154203/WordPress-Import-Export-WordPress-Users-1.3.1-CSV-Injection.html - http://packetstormsecurity.com/files/154203/WordPress-Import-Export-WordPress-Users-1.3.1-CSV-Injection.html - https://hackpuntes.com/cve-2019-15092-wordpress-plugin-import-export-users-1-3-0-csv-injection/ - https://hackpuntes.com/cve-2019-15092-wordpress-plugin-import-export-users-1-3-0-csv-injection/ - https://wpvulndb.com/vulnerabilities/9704 - https://wpvulndb.com/vulnerabilities/9704 #### Github - https://github.com/0xZipp0/BIBLE - https://github.com/301415926/PENTESTING-BIBLE - https://github.com/84KaliPleXon3/PENTESTING-BIBLE - https://github.com/ARPSyndicate/cvemon - https://github.com/Ashadowkhan/PENTESTINGBIBLE - https://github.com/JavierOlmedo/JavierOlmedo - https://github.com/Mathankumar2701/ALL-PENTESTING-BIBLE - https://github.com/MedoX71T/PENTESTING-BIBLE - https://github.com/Micle5858/PENTESTING-BIBLE - https://github.com/NetW0rK1le3r/PENTESTING-BIBLE - https://github.com/OCEANOFANYTHING/PENTESTING-BIBLE - https://github.com/Rayyan-appsec/ALL-PENTESTING-BIBLE - https://github.com/Saidul-M-Khan/PENTESTING-BIBLE - https://github.com/alphaSeclab/sec-daily-2019 - https://github.com/bjknbrrr/PENTESTING-BIBLE - https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE - https://github.com/codereveryday/Programming-Hacking-Resources - https://github.com/cwannett/Docs-resources - https://github.com/dli408097/pentesting-bible - https://github.com/erSubhashThapa/pentest-bible - https://github.com/gacontuyenchien1/Security - https://github.com/guzzisec/PENTESTING-BIBLE - https://github.com/hacker-insider/Hacking - https://github.com/iamrajivd/pentest - https://github.com/imNani4/PENTESTING-BIBLE - https://github.com/mynameiskaleb/Coder-Everyday-Resource-Pack- - https://github.com/neonoatmeal/Coder-Everyday-Resource-Pack- - https://github.com/nitishbadole/PENTESTING-BIBLE - https://github.com/phant0n/PENTESTING-BIBLE - https://github.com/readloud/Pentesting-Bible - https://github.com/ridhopratama29/zimbohack - https://github.com/t31m0/PENTESTING-BIBLE - https://github.com/vincentfer/PENTESTING-BIBLE- - https://github.com/whoami-chmod777/Pentesting-Bible - https://github.com/yusufazizmustofa/BIBLE